Incident Response Tooling

Pharos by Helm

Read-only evidence collection for business and consumer email compromise investigations — bringing the available mailbox, account activity, and connected-app evidence into focus. Direct integrations for Google Workspace and Microsoft 365, with investigation support across other mail providers.

Pharos by Helm logo — an ornate shield framing a lighthouse casting its beam across streams of binary

What It Is

Evidence Collection, Not Another Security Product

Pharos is a tool built and operated by Helm Information Security for use in our own business email compromise investigations. It is not a monitoring platform, a security scanner, or a mail client.

When an email account is compromised, the evidence that matters is scattered across mailbox rules, message headers and content, sign-in history, administrative activity, recovery settings, and connected applications. The exact evidence available varies by provider, but gathering it during an active incident is consistently slow and error-prone.

Pharos automates collection from supported platforms and gives our investigators a consistent process for provider-supplied evidence, so the investigation starts with facts instead of guesswork.

What It Collects

  • Mail filters, forwarding addresses, delegation, and recovery settings where available
  • Message headers and content for the specific mailboxes and date ranges under investigation
  • Sign-in and account activity, including IP addresses, geography, and authentication details where available
  • Connected-application and delegated-access records exposed by the provider
  • Administrative, sharing, and security-setting changes for managed business environments
  • Account and directory information needed to establish the scope of the incident

How It Works

Authorized by your organization or the account owner, scoped to the incident, and revocable where direct access is used.

1
You engage Helm for an incident

Pharos is only used inside a signed engagement. There is no self-service signup — access is provisioned per client, per incident.

2
Authorized access is established

For Google Workspace and Microsoft 365, the collection application is deployed inside your own Google Cloud project or Microsoft tenant as an internal application of your organization. Your administrators own it, grant it the permissions the investigation needs, and can revoke it at any time. Your organization's mail is never reached through an application published by Helm. For consumer accounts, the account owner gathers evidence using the exports and security records the provider makes available, with our guidance. We explain what evidence is available before collection begins.

3
We collect the evidence in scope

Collection is read-only and bounded by the mailboxes and date range agreed in the engagement letter. The app never sends mail, never modifies settings, and never deletes anything.

4
You receive findings — and access is closed

We deliver the investigation report. Any direct application authorization is revoked through the relevant provider, and collected data is retained or destroyed on the schedule set in the engagement letter.

Email Provider Coverage

The investigation follows the evidence each provider makes available. Access method and collection depth vary by platform.

Google Workspace

Direct, administrator-authorized collection of Gmail messages and settings, Workspace audit activity, connected applications, and directory information relevant to the investigation. The application is deployed as an internal app in your own Google Cloud project, so your administrators own it and can revoke it without involving us.

Microsoft 365

Direct, administrator-authorized collection from Exchange Online, Entra ID, Microsoft Graph, and the unified audit log for the accounts and period under investigation.

Consumer and Other Mail

Investigation support for Gmail, Outlook.com and Hotmail, Yahoo Mail, AOL Mail, and other providers using the account records, exports, and security evidence each service makes available. The account owner retrieves this evidence, such as data exports, sign-in history, and forwarding and recovery settings, with our guidance. No third-party application access to the account is required.

Read-only investigation

Pharos uses provider permissions only for read operations and does not send, modify, or delete mail or change customer account settings. Remediation is performed by the client or account owner, with our guidance.

How We Handle Investigation Data

These controls apply to evidence collected from Google Workspace, Microsoft 365, and other mail providers. Investigation evidence is some of the most sensitive data an organization has, and we treat it accordingly.

🔒
Encrypted in transit and at rest

All API access uses TLS. Collected evidence is stored encrypted at rest in an access-controlled case repository, separated per client engagement.

👤
Access limited to the case team

Only the Helm personnel assigned to your engagement can access your data. Access requires multi-factor authentication and is logged.

🗓️
Retained only as agreed

Evidence is retained for the period set in your engagement letter — to support insurance claims, law enforcement referrals, or litigation — then securely destroyed. You can request earlier deletion.

🚫
Never sold or used for advertising

We do not sell or rent investigation data, and we never use it for advertising, marketing, or credit-related purposes. We share it only as permitted by your engagement agreement.

🤖
No training on identifiable data

We do not use identifiable client or personal data to train generalized AI models. Where permitted, we may use de-identified or aggregated non-Google information that cannot reasonably be linked to a client or individual to improve security detections and analytical models. We do not use Google Workspace data obtained through Google APIs — including messages, settings, directory information, audit logs, or information derived from that data — to create, train, or improve generalized AI or machine learning models.

↩️
Revocable at any time

Where direct provider access is used, the client administrator or account owner can revoke that access through the provider. Revocation stops further collection but does not delete evidence already collected.

Support and Contact

Pharos is developed and operated by Helm Information Security, a cybersecurity consultancy based in Wisconsin. Questions about the application, its data handling, or an active authorization go to the same team that runs the investigations.

Responding to a Compromise Now?

Pharos is one part of our email compromise response engagement. If an account is compromised today, start there — the tooling follows the engagement.

Email Compromise Response